Skip to content

Latest commit

 

History

History
19 lines (14 loc) · 772 Bytes

File metadata and controls

19 lines (14 loc) · 772 Bytes

Security Policy

Reporting a Vulnerability

Supported Versions

  • Main branch; tagged releases.

Expectations

  • Do not test against production deployments you don’t own.
  • Avoid exploiting beyond proof of concept; share logs/traces if safe.

Out of Scope

  • Social engineering, physical attacks, or issues requiring privileged local access outside OCPA.

Pre-release checks

  • Run a secret scan (gitleaks/trufflehog) on history before public releases; actions are wired to allow scans on demand.